GHSA-p3qg-v7px-94h6MediumCVSS 6.5

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs()...

Published
September 24, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.

🔗 References (3)